Stop Information Leakage: Web Server AnonymizationObscure Headers, Cookies, & Error Messages | ||
Remove Unnecessary HTTP Header & Response DataBroadcasting your Web server's identity allows intruders to complete their first task -- fingerprinting your technology. ServerMask removes unnecessary HTTP header and response data and camouflages your server by providing false signatures. Eliminate File ExtensionsFile extensions like .asp or .aspx are clear indicators that a site is running on a Microsoft server. ServerMask eliminates the need to serve file extensions. Modify Cookie ValuesThe ASP session ID cookie, used by the Session object to maintain client state, is a dead giveaway to the type of server you are running. ServerMask can modify your cookie values so that they are generic in nature and non identifiable. Custom Error PagesDefault messages, pages and scripts of all kinds often contain clues to server identity. ServerMask custom error pages mask that information for better security. Anti-ReconnaissanceInformation masking encourages misguided exploits, snaring attackers with your firewalls and Intrusion Detection System. ServerMask augments these defenses to build more secure networks and return better results on security audits. Support and Upgrades
|
Pricing
Learn more |
|
What ServerMask Does:
Contributes to PCI ComplianceServerMask provides application-layer error suppression for PCI compliance. Per-site ConfigurationServerMask allows for multiple default profiles and the ability to create custom profiles, allowing unique settings to be applied per domain. Masks Server Name HeaderServerMask will mask the Server name header in a number of ways:
Rewrite Identifying Session Cookie NamesServerMask will rewrite identifying session cookie names, such as ASPSessionID and ASP.NET_SessionId, using one or more alternative names and fabricate decoy cookies to further confuse attackers. ServerMask utilizes One-to-many cookie masking. Rewrite 404 & Application-layer ErrorsServerMask suppresses info leakage by converting 500-range errors to 404 errors, then presenting custom 404 responses. Remove Identifying File ExtensionsServerMask removes identifying file extensions, such as .asp, .aspx and other Microsoft technologies from source code and URL display. |
Remove unnecessary HTTP headersServerMask removes unnecessary HTTP headers, such as PUBLIC, X-POWERED-BY and others. Emulate Other Server DataServerMask will emulate the ETAG and ALLOW header formats of non-IIS servers. (As well as Apache's HTTP header order.) Decoys & Error MessagesServerMask provides Auto-generated decoy cookies and headers, and customizable HTTP error messages. Diagnostics & ValidationOnline diagnostic tool for checking page cacheability and validation tool provided for checking syntax of rule statements Ease of UseCompletely redesigned user interface, featuring 100% managed code. |
System Requirements
- OS: Windows Server 2003 with Service Pack 2 or Server 2000 with SP4
- Hardware: x86 (32-bit) or x64 (64-bit)
- Note: IIS 7 / Windows Server 2008 not yet supported (sign up for the IIS 7 Beta Alert)
The following runtimes are also required but can be installed by the ServerMask installer if not already present on the target system:
- .Net 2.0 (or higher)
- Visual C++ 2005 SP1

Starting at $199.95
